CVE-2026-2670
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Summary
A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. Affected is an unknown function of the file /cgi-bin/luci/admin/openvpn_apply of the component Background Management. Such manipulation of the argument delete_file leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used. Upgrading to version 1.2.4_20260821 is able to address this issue. It is advisable to upgrade the affected component. The vendor explains: "The delete operation has been redesigned to map the requested file type to a fixed allowlisted path, require a numeric tunnel ID, reject invalid requests, and use the native filesystem API (fs.unlink) instead of constructing a shell command from request data."
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Advantech | WISE-6610-NB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-NB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-TB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-TB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-JB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-JB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-CB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-CB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EL-NB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EL-NB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EL-EB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EL-EB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EL-TB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EL-TB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EL-JB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EL-JB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610-EL-CB | 1.2.1_20251110 | affected |
| Advantech | WISE-6610-EL-CB | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610P-DEA | 1.2.1_20251110 | affected |
| Advantech | WISE-6610P-DEA | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610P-DNA | 1.2.1_20251110 | affected |
| Advantech | WISE-6610P-DNA | 1.2.4_20260821 | unaffected |
| Advantech | WISE-6610P-DTA | 1.2.1_20251110 | affected |
| Advantech | WISE-6610P-DTA | 1.2.4_20260821 | unaffected |
Weaknesses
- CWE-78: OS Command Injection
- CWE-77: Command Injection
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
References
- https://vuldb.com/vuln/346467
- https://vuldb.com/vuln/346467/cti
- https://vuldb.com/cve/CVE-2026-2670
- https://vuldb.com/submit/753293
- https://github.com/master-abc/cve/issues/37
- https://www.advantech.com/zh-tw/security-advisory
- https://www.advantech.com/en-us/support/details/firmware?id=1-2K7AXRI
- https://www.advantech.com/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.